Access and customer management in Norce Commerce
A commerce platform is used by many people, in many ways. Buyers, merchandisers, pricing managers, integration teams and end customers all interact with different parts of the same system. Norce Commerce gives you the tools to make sure everyone gets exactly the access they need, no more, no less.
For the admin interface, access control works in two layers. The first is at the client level, where you configure which modules are visible at all, and whether they can be read and edited or viewed only. Products, pricing, categories, promotions, customers, suppliers, integrations, each section can be switched between full access, read-only, or completely hidden. Many sections go further, letting you control individual fields: mark them as required, rename them to match your internal terminology, or add help text that guides users on how to fill them in correctly.
The second layer is roles. Each role inherits the client-level configuration as its starting point, and from there you can narrow permissions further. A pricing manager can be given full access to price lists but read-only access to the product catalogue. A content editor can enrich product data without seeing customer or order information. Roles can only remove permissions, not add beyond what the client level allows, which keeps the permission model clean and predictable.
For organisations that already manage identity centrally, Norce now supports Single Sign-On for the admin interface. Admin users can authenticate through a third-party identity provider (currently Microsoft Entra), which means no separate credentials to manage, password policies are handled centrally, and access can be revoked instantly when someone leaves the team.
This is how Norce keeps teams working in the same platform without stepping on each other's toes and without opening sensitive data to people who do not need it.
The same logic of structured access extends to how Norce models your end customers. In Norce, Customers are always individuals, real people with names, email addresses, and delivery information. Companies are organisations, and customers connect to them as contacts. One person can belong to multiple companies, and one company can have many contacts, a structure that maps naturally onto how B2B relationships actually work.
Companies often carry their own pricing logic. Contract price lists, company-specific discounts, exclusive agreements, and custom payment and delivery methods can all be configured per company, ensuring that when a logged-in customer shops on behalf of their employer, they see exactly the terms that have been negotiated for that account. Customers can also be tagged with flags for segmentation, loyalty status, or integration purposes, and extended with custom info fields to store whatever additional data your business requires.
Together, the admin permission model and the customer model reflect the same principle: the right access for each type of user.